PT-2025-37110 · Unknown · Binary-Husky/Gpt Academic

D3Do

·

Published

2025-09-11

·

Updated

2025-09-11

·

CVE-2025-10236

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: binary-husky gpt academic versions up to 3.91
Description: A path traversal issue exists in the LaTeX File Handler component of binary-husky gpt academic. The merge tex files function within the crazy functions/latex fns/latex toolbox.py file is susceptible to manipulation of the input{} argument, potentially allowing for path traversal. The exploit has been publicly disclosed. The vendor was contacted but did not respond.
Recommendations: Versions prior to 3.91 should be used.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-10236

Affected Products

Binary-Husky/Gpt Academic